antigravity-workflows
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a standard orchestration tool with no identified security vulnerabilities. It facilitates structured execution of complex tasks and explicitly instructs the agent to seek user approval for destructive actions and ensure authorization for security audits.
- [PROMPT_INJECTION]: Analysis of indirect prompt injection potential (Category 8). The skill reads workflow definitions from local project files, which serves as an ingestion point for external data that could influence the agent's behavior.
- Ingestion points:
docs/WORKFLOWS.mdanddata/workflows.jsonas specified inSKILL.md. - Boundary markers: None explicitly defined to separate workflow instructions from user data.
- Capability inventory: Orchestrates and invokes other skills, providing a high degree of agent autonomy during workflow execution.
- Sanitization: No evidence of validation or sanitization of the content within the ingested markdown or JSON workflow files.
Audit Metadata